New Citrix NetScaler SAML Flaw CVE-2026-88779 Exploited in Zero-Day Attacks

Citrix released emergency patches for CVE-2026-88779, a high-severity memory buffer flaw in NetScaler ADC and Gateway appliances using SAML authentication. The vulnerability, which carries a CVSS score of 8.7, is being actively exploited in targeted attacks to cause denial-of-service conditions. While Citrix characterizes the issue as a service availability risk, researchers and administrators report evidence of remote code execution attempts, including malware payloads on patched systems. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by October 7, 2026. This latest incident follows a wave of exploitation of earlier NetScaler vulnerabilities in September 2026, affecting dozens of organizations across government, healthcare, and finance sectors.
Key points
- Citrix patched CVE-2026-88779, a memory overflow vulnerability in NetScaler ADC and Gateway that affects SAML service provider and identity provider configurations.
- The flaw has a CVSS score of 8.7 and is confirmed to be exploited in targeted attacks causing denial-of-service, with repeated triggers potentially leaving services unavailable.
- Researchers and administrators observed signs of remote code execution, including crafted authentication usernames containing shell commands and malware payloads on patched honeypots.
- CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog, requiring federal agencies to mitigate the flaw by October 7, 2026.
- This vulnerability emerged shortly after Citrix patched CVE-2026-88771 and CVE-2026-88772, forcing organizations that recently upgraded to patch again to address the new SAML-specific flaw.
Background
This development follows a series of critical NetScaler vulnerabilities disclosed in September 2026. Earlier in the month, Citrix patched CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on the CVSS scale, which were actively exploited to deploy web shells and tunneling tools. The exploitation of these earlier flaws affected dozens of organizations across North America and Europe, including healthcare providers and government agencies. The current CVE-2026-88779 incident indicates that threat actors are continuing to target NetScaler infrastructure, with some researchers drawing parallels to previous vulnerabilities that were initially characterized as denial-of-service but later shown to enable remote code execution.
How outlets are covering it
BleepingComputer and The Hacker News report that Citrix officially characterizes CVE-2026-88779 as a denial-of-service vulnerability, noting that it affects service availability but not customer data integrity. However, BleepingComputer highlights that cybersecurity researchers and NetScaler administrators have observed activity suggesting the flaw can be exploited for remote code execution, including crafted shell commands and malware payloads on patched systems. Cybersecurity Dive provides broader context, noting that the exploitation of earlier NetScaler vulnerabilities (CVE-2026-88771 and CVE-2026-88772) affected dozens of organizations and was linked to suspected state-linked actors. Palo Alto Networks' Unit 42 detailed the technical exploitation of the earlier vulnerabilities, including web shell deployment and command injection chains, but did not provide specific technical details on the new CVE-2026-88779 flaw. All sources agree that immediate patching is critical, with Citrix urging customers to upgrade to the latest releases and CISA mandating federal agencies to patch by October 7, 2026.
Why it matters
The active exploitation of CVE-2026-88779 underscores the ongoing risk posed by Citrix NetScaler appliances, which are widely used for secure remote access and application delivery across critical sectors. The potential for remote code execution, even if not officially confirmed by Citrix, raises concerns about data integrity and system compromise beyond mere denial-of-service. The rapid succession of NetScaler vulnerabilities in 2026 highlights the need for organizations to prioritize patch management and consider temporary mitigation measures, such as disabling vulnerable systems or blocking malicious IP addresses, to protect against targeted attacks. The involvement of CISA and the mandate for federal agencies to patch by October 7, 2026, signals the severity of the threat and the urgency with which organizations must respond.
What to watch
Organizations should immediately check if their NetScaler deployments are configured with SAML authentication and apply the latest security updates released by Citrix. Those who recently upgraded to patch CVE-2026-88771 through CVE-2026-88778 must upgrade again to address CVE-2026-88779. Federal agencies must comply with CISA's mandate to patch by October 7, 2026. Security teams should monitor for signs of compromise, including unexpected reboots, nsaaad crashes, and anomalous authentication requests, and consider isolating vulnerable systems from the network if patching is not immediately possible. Researchers and administrators should continue to investigate whether the flaw can be exploited for remote code execution, as evidence suggests it may go beyond denial-of-service.
- Citrix patches NetScaler SAML zero-day exploited in attacks BleepingComputer
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline thehackernews.com
- Mass exploitation of Citrix NetScaler: What we currently know Cybersecurity Dive
- Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) unit42.paloaltonetworks.com
- Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response Dark Reading
Want the full story? Read the original reporting
Read on BleepingComputer